Helidon Vulnerability in Oracle Fusion Middleware Affects Imperative Web Server
CVE-2026-73930

9.9CRITICAL

Key Information:

Vendor

Oracle

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-73930?

The Helidon product within Oracle Fusion Middleware is susceptible to an unauthenticated access vulnerability that can be exploited through HTTP. An attacker with network access can compromise Helidon, leading to unauthorized creation, deletion, or modification of data. Furthermore, the vulnerability allows unauthorized read access to some Helidon data and the potential to trigger a partial denial of service (DoS). This vulnerability's impact extends beyond Helidon itself, possibly affecting other interconnected products, making it essential for users to apply the necessary security updates.

Affected Version(s)

Helidon 4.5.3

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.